Impact
A flaw in the CipherConnectionAction module of O2OA versions up to 9.5.3 and 10.0.2 allows an attacker to tailor the fileUrl argument and retrieve sensitive data remotely. The vulnerability is classified as Information Exposure (CWE‑200) and Improper Authorization (CWE‑284). Successful exploitation grants an unauthorized party reading access to information that should be protected, potentially compromising the confidentiality of the system.
Affected Systems
O2OA deployments running version 9.5.3 or earlier and 10.0.2 or earlier, specifically the Cipher Connection Handler component accessed via the list function in CipherConnectionAction.java.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. No EPSS score is publicly available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower immediate threat posture but still open for exploitation. Because the attack vector is remote and does not require authentication, an attacker can easily craft a request with a malicious fileUrl to trigger the disclosure.
OpenCVE Enrichment